Sponsorships when you have a day job in security

Most of the people a security brand actually wants to work with are not full time creators. They are a detection engineer who writes a very good newsletter on the side. An appsec lead who speaks at two conferences a year. A threat researcher whose blog is the reason half an industry understands a particular malware family.

The day job is not a distraction from their credibility. It is their credibility. It is also the single most common way a sponsorship turns into a problem, and almost nobody raises it before the deal is agreed.

Your employer has a position on this whether you asked or not

Plenty of practitioners assume that what they do on their own time, on their own account, is nobody else’s business. Sometimes that is true. Often it is not, and the discovery happens at the worst possible moment: after the post is live, after the money has moved, when someone in legal or procurement notices that an employee is being paid by a vendor the company is currently evaluating.

Nobody wins that conversation. The creator looks like they hid something even if they did not. The brand looks like it bought access. Neither was the intention.

Read three documents before you reply to the offer

This takes about twenty minutes and it is the highest value twenty minutes in the whole deal.

  • Your employment agreement. Look for the outside work or moonlighting clause. Some require written approval for any paid outside activity. Some only care if it competes.
  • The IP assignment clause. Broadly written ones can claim work created in your field during your employment, which in theory reaches your blog. Most employers never enforce this. You still want to know it exists before you sign a contract granting a brand usage rights to that work.
  • The policy handbook. Social media policy, outside speaking, and the gifts and vendor relationships section. If you work in a bank, a government contractor, or anywhere with a procurement ethics regime, a payment from a vendor may be something you are formally required to declare.

Conflict of interest is wider than direct competition

The obvious case is taking money from a competitor of your employer. The cases that cause more trouble are quieter:

  • A vendor your team is currently in a proof of concept with.
  • A vendor you already use, where you sit anywhere near the renewal decision.
  • A vendor whose sales team could plausibly reach your employer through you.

None of these are automatically disqualifying. All of them need to be surfaced, in writing, before anything is signed. A conflict disclosed early is an administrative step. The same conflict discovered later is an incident.

What you cannot sell at any price

There is a clean line here and it is worth stating plainly. You can promote based on your public work. You cannot promote based on your privileged position.

That rules out incident details, internal architecture, detection logic your employer owns, telemetry, contract terms, and anything you know only because of where you work. It also rules out your employer’s name used as an implied endorsement. A post that reads as if a well known company has adopted a product, when what actually happened is that one of its engineers was paid to write about it, is misleading regardless of how the disclosure is worded.

And it rules out selling access. If any part of the value being purchased is an introduction to your employer, that is not a sponsorship. That is something else, and it can end a career.

Get the approval in writing, then put it in the contract

A short email to your manager is usually enough: what the brand is, what you will produce, that it is on your own time and equipment, that no company information is involved, and that it will be disclosed as an ad. Ask for a written yes. Keep it.

Then reflect it in the creator contract. Two clauses are worth having: one that lets you withdraw without penalty if your employer objects before publication, and one confirming you are contracting in a personal capacity, not on behalf of your employer.

Note that this is now two separate disclosures with two different audiences. The #ad label is for your readers and is a legal requirement. The internal declaration is for your employer and is a professional one. A bio that says views are my own does neither job.

What brands should do about it

Ask in the first conversation, not the last. Where do you work, and is there anything about this campaign that creates a problem for you there? It is a normal question and a good creator will respect you for asking it.

Then build a timeline that survives the answer. If approval is needed, that is a week you did not plan for. Never suggest the creator keep the deal quiet at work, and never structure a deal so that the creator’s employer is the real target. Any brand that does either is telling you exactly how it will behave later.

Where we sit on this

Influous is pre-launch, so we are describing how we are building this rather than reporting results. Our vetting verifies identity and employment, which means the conflict question comes up early by design rather than by accident. We would rather lose a match than put a creator into a campaign that costs them the job that made them credible in the first place.

If you write, speak, or research in security alongside a full time role and you want that reflected properly in how you are matched, you can apply as a creator. If you are a brand and you want the employment question handled before a campaign starts rather than after, email us at info@influous.io.

Share

Be in the founding cohort

One managed campaign, run end to end

Influous runs influencer campaigns for security and tech brands with hand-picked, vetted creators. Pre-launch, founding cohort forming now.

Discover more from Influous

Subscribe now to keep reading and get access to the full archive.

Continue reading